
Penetration Tester
SourcingXPress • Bengaluru, Karnataka, India
Salary: INR 1,000,000 - INR 1,800,000 / year
**Role & seniority: ** Penetration Tester (Offensive Security), 2+ years professional experience (mid-level)
**Stack/tools: **
-
Testing: Burp Suite Pro, Metasploit, Nmap, Cobalt Strike
-
Methodologies: OWASP Top 10, Active Directory attack paths
-
Cloud: AWS/Azure
-
Scripting/automation: Python, Go, Bash
-
Targets: Web/mobile apps, APIs, AI agents, networks, cloud
-
Top 3 responsibilities:
-
Perform full-scope offensive security on web/mobile, APIs, AI agent systems, networks, and cloud
-
Manually exploit vulnerabilities and produce risk analysis that reflects business impact
-
Write actionable reports and collaborate with engineering teams to guide/validate remediation
-
-
Must-have skills:
-
Hands-on offensive security experience (2+ years)
-
Proficiency with OWASP Top 10 and AD attack paths
-
Strong command of offensive tooling (Burp/Metasploit/Nmap/Cobalt Strike)
-
Clear technical writing; ability to explain risk to non-technical stakeholders
-
-
Nice-to-haves:
-
OSCP preferred (or equivalent: OSWE, OSEP, CRTO)
-
Experience building custom automation scripts and workflows
-
-
Location & work type: Not specified in provided text. Salary: ₹10–18 LPA; company: Seed-stage B2B security startup (product & service).
Full Description
Company: Deep Armor
Website: Visit Website
LinkedIn: Visit LinkedIn
Business Type: Startup
Company Type: Product & Service
Business Model: B2B
Funding Stage: Seed
Industry: security
Salary Range: ₹ 10-18 Lacs PA
Job Description
Penetration Tester (Offensive Security)
About The Role
We're looking for an experienced Penetration Tester to join our security team, focused on full-scope offensive security engagements across web/mobile applications, APIs, AI agents, networks, and cloud environments (AWS/Azure).
Core Responsibilities
Full-Scope Penetration Testing — Conduct manual and automated security assessments on web and mobile applications, APIs, AI agent systems, internal/external networks, and cloud infrastructure (AWS/Azure) Exploitation & Risk Analysis — Manually exploit identified vulnerabilities to demonstrate real-world business impact, going beyond automated scan results Reporting & Remediation — Author clear, actionable technical reports and partner directly with development teams to guide and validate fix implementation Tooling & Automation — Build and maintain custom scripts (Python, Go, or Bash) to automate testing workflows and bypass modern security defenses
Must-Have Qualifications
Experience: 2+ years of dedicated professional experience in offensive security / ethical hacking
Technical Expertise: Strong working knowledge of the OWASP Top 10, Active Directory attack paths, and industry-standard tooling (Burp Suite Pro, Metasploit, Nmap, Cobalt Strike)
Certifications: OSCP preferred; equivalent certifications (OSWE, OSEP, CRTO) considered a strong plus
Communication: Excellent technical writing skills, with the ability to translate complex vulnerabilities into business risk for non-technical stakeholders